CVE-2026-80599
Last modified
CVE-2026-80599 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: ensure accessible eth_hdr proto field When batadv_get_vid() accesses the proto field of the ethernet header, it is not checking if the data itself is accessible. The caller is responsible for it. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: ensure accessible eth_hdr proto field When batadv_get_vid() accesses the proto field of the ethernet header, it is not checking if the data itself is accessible. The caller is responsible for it. But in contrast to other call sites, batadv_dat_get_vid() and its caller didn't make sure this is true. This could have caused an out-of-bounds access.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= be1db4f6615b5e6156c807ea8985171c215c2d57, < da3677b5ed362742d30ceab31bfafcdc74dc2642; >= be1db4f6615b5e6156c807ea8985171c215c2d57, < 6d3ea37074bb747f745d28138f87745ba9bd97c5; >= be1db4f6615b5e6156c807ea8985171c215c2d57, < 7913935d41f166c367bbf7cc76a79e50044388e8; >= be1db4f6615b5e6156c807ea8985171c215c2d57, < 3c62694c31f043568c3f4784b8d247cc3bea6b4c; >= be1db4f6615b5e6156c807ea8985171c215c2d57, < 5836a050d02e9598fa0f71e88dde28b63dfa35e3; >= be1db4f6615b5e6156c807ea8985171c215c2d57, < 8f76277d02176cd739945bba3379448e2e22e799; >= be1db4f6615b5e6156c807ea8985171c215c2d57, < 4407ff3af469356f9641c4a6e7072309bae86bea; >= be1db4f6615b5e6156c807ea8985171c215c2d57, < 26560c4a03dc4d607331600c187f59ab2df5f341 |
| Linux | Linux | 3.13 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80599?
How severe is CVE-2026-80599?
How do I fix CVE-2026-80599?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80593In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-80594In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80595In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80596In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-80597In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80598In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80600In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-80601In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-80602In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80603In the Linux kernel, the following vulnerability has been re…9.1
- CVE-2026-80604In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-80605In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-80599?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
